Joomunited

Wp File Download

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 10.10.2026 06:40:12
  • Zuletzt bearbeitet 10.10.2026 07:16:42

The WP File Download plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.3.9. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for a...

  • EPSS 0.68%
  • Veröffentlicht 05.09.2026 06:37:56
  • Zuletzt bearbeitet 08.09.2026 13:12:58

The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.8 via the 'remoteurl' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to r...

  • EPSS 0.52%
  • Veröffentlicht 02.09.2026 02:26:43
  • Zuletzt bearbeitet 04.09.2026 03:17:40

The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all versions. This makes it possible for authenticated attackers, with subscriber-level access and a...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 21.06.2025 06:15:18
  • Zuletzt bearbeitet 02.07.2025 19:00:24

The wp-file-download WordPress plugin before 6.2.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting